How Education Tackles Cybersecurity

How Education Tackles Cybersecurity 

With technology becoming a cornerstone of how many school districts operate, the risks of getting hacked multiplies, and defending against cyber-attacks becomes an important part of any strategic plan. A new report from the IBM X-Force finds attackers are drawn to the education sector owing to the sensitive nature of some emerging research projects and personally identifiable information on students, faculty and organizations associated with universities and schools.

Despite all of these risks, the education sector comes in at ninth place among the most targeted industries, according to the 2019 IBM X-Force Threat Intelligence Index 2019. The most attractive industries for hackers include finance and insurance, transportation services, retail and manufacturing.

There are many risks in the school environment ranging from having poor security protocols in place to dealing with a large network of users who can bring malware into their networks through personal devices or email. “Aside from nation-states, educational institutions may be targeted by financial criminals looking to take over bursary accounts and student identities. Another relevant threat [is] hacktivists looking to champion a cause by holding an institute for ransom or threatening to release stolen data,” the report finds.

By identifying the threats, the report argues that it can help institution craft better solutions. Emerging and relentless threats include:

  • Financially motivated cybercriminals and nation-state groups that target a wide range of industries.

  • Attackers who direct their efforts and use of cloud services and misconfigured cloud servers that expose customer and employee data.

  • The exploitation of an institution’s supply chain or third-party relationships that can allow hackers to gain access to their primary targets.

When it comes to remediating these attacks, IBM X-Force is suggesting that organizations should conduct mutual penetration testing along with automated scanning. Students and faculty should also be educated on phishing and malware efforts to help institutions mitigate these threats. Organizations should also be doing exercises to determine how to respond to simulated cyber attacks and continuously innovate and share ideas with other response teams to share successful practices.

The full report is available for download here.

About the Author

Sara Friedman is a reporter/producer for Campus Technology, THE Journal and STEAM Universe covering education policy and a wide range of other public-sector IT topics.

Friedman is a graduate of Ithaca College, where she studied journalism, politics and international communications.

Friedman can be contacted at [email protected] or follow her on Twitter @SaraEFriedman.

Click here for previous articles by Friedman.


Featured

  • digital lock

    CoSN: Cybersecurity and Data Privacy Remain Top AI Concerns in Education

    A leading concern for education technology leaders across the United States is the potential for AI to enable new forms of cyber attacks, according to the latest State of Ed Tech report from CoSN.

  • lock symbol with quantum bits in dynamic motion

    Microsoft Accelerates Quantum-Safe Security Timeline

    Microsoft is speeding up its quantum-safe security timeline, noting that advances in quantum computing and new federal requirements have pushed post-quantum cryptography from a future planning issue into an immediate engineering priority.

  • large cloud icon on the right in an abstract world above a polygon with a dark blue background

    Cloud Security Alliance Expands Agentic AI Governance Work

    The Cloud Security Alliance (CSA) has announced a series of CSAI Foundation milestones aimed at securing what it calls the agentic control plane, including a new catastrophic risk initiative, CVE Numbering Authority authorization, and the acquisition of two agentic AI specifications.

  • abstract smartphone translucent screen displaying AI interface

    Apple Unveils Redesigned Siri AI

    At its recent Worldwide Developers Conference, Apple announced Siri AI, a redesigned version of its voice assistant that Apple describes in its own announcement as "a profoundly more capable and personal assistant." The update is intended to make Siri more conversational, more context-aware, and more useful across iPhone, iPad, Mac, Apple Watch, and Vision Pro.